Unauthorized data access
Test whether an employee can obtain another employee's salary, performance-review, or job-transfer information through AI.
We test whether an AI agent stays within the authorized user, data, action, tool, and network boundaries by executing realistic business scenarios and preserving traceable evidence.
Agents interpret natural language and choose tools and data sources. A restriction on one path may be bypassed through another service account, API, index, or file store.
Test whether an employee can obtain another employee's salary, performance-review, or job-transfer information through AI.
Verify that denial by the primary HR database does not lead the agent to a DWH, file store, RAG index, or another API.
Repeat equivalent requests to determine whether authorization and denial behavior remain consistent.
A high-level description of the agent, users, connected systems, and boundary concerns is enough for an initial discussion.